The 2009 Pwnie Nominee For Best Client-Side Bug

LittleCMS (CVE-2009-0733)

Credit: Chris Evans

No, LittleCMS is not some budding programmer’s first PHP content management system. It’s one of those subtle (and buggy) libraries that ends up burrowing its way into too many other products. In thise case, LittleCMS is a color management library used to handle color profiles for JPEG images. And this little library that could happened to find itself used by ImageMagick, OpenJDK, and some beta releases of Firefox 3.1. Throw in some memory corruption and that’s enough to 0wn up some Linux desktops.

(CVE-2009-0733)